Google Cloud / Mandiant (GTIG)
mandiant-gtig · B · active
https://cloud.google.com/blog/topics/threat-intelligence
Google Threat Intelligence Group; absorbed Mandiant CTI. The /topics/threat-intelligence landing lists titles but NO publication dates (only relative read times). Drill rule: open the top 3-5 posts on the listing and read their date inline rather than treating the dateless landing as empty. RSS at https://cloud.google.com/blog/topics/threat-intelligence/rss is a partial mirror (truncated). (v2.55: rss_url verified, use `python3 tools/fetch_source.py feed https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v [N]`) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v 5 (dated listing) then webfetch the per-article cloud.google.com URL for the body; the HTML landing also works for titles but carries no dates. AVOID: The /topics/threat-intelligence HTML landing has titles but NO publication dates (only relative read-times), use the feedburner RSS for dates rather than treating the dateless landing as the index. The cloud.google.com/.../rss mirror is truncated.. | 2026-07-05 admiralty audit: B, GTIG/Mandiant original first-hand threat research. Reliability HIGH->B, status stays active. Use feedburner RSS for dates (HTML landing is dateless).
Cited in 20 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 17).
- ANNUAL REPORT; Mandiant AI Risk and Resilience Report 2026: eight frontline case studies of AI agents weaponized inside real intrusions and red-team engagements2026-09-17
- Unit 42 exposes two Latin American intrusion clusters after their own AI-agent staging infrastructure was left open, one hit Mexican federal ministries and water utilities, the other Brazilian finance2026-09-04
- GTIG Agentic Vulnerability Discovery Harness (AVDH): Mandiant's multi-agent pipeline found 100+ true-positive critical vulnerabilities in a stolen corporate source-code repository within two days2026-08-28
- A hijacked crates.io account added the first dependency arrayref has taken in ten years, and that dependency ran a backdoor at compile time; every machine that built an affected project during a ninety-minute window must be treated as compromised2026-08-23
- Three Russia-nexus espionage clusters compromise European diplomats and academics without malware, by talking targets through app passwords, device-code approvals and WhatsApp device-linking, all of which are legitimate features working as designed2026-08-23
- UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey2026-08-07
- Mandiant "Ghost in the Database": recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails2026-07-09
- Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection2026-06-27
- Cisco Catalyst SD-WAN Manager CVE-2026-202452026-06-26
- Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor2026-06-21
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule2026-06-16
- CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session2026-06-13
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration2026-06-11
- Unit 42: Microsoft Teams external-chat now a primary phishing surface for APT29 and UNC66922026-06-09
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services2026-06-06
- CVE-2026-20245, Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no patch)2026-06-06
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage2026-05-26
- CVE-2026-5426, Digital Knowledge KnowledgeDeliver LMS: pre-shared ASP.NET machineKey enables ViewState deserialization RCE, exploited as a zero-day2026-05-26
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand2026-05-16
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12